8 ms·
Apple announces bug bounty program
- hurricaneSlider 10y agoI'm a bit surprised, because you'd think that they'd have been doing this already.
- bpchaps 10y agoI had the.. pleasure.. of speaking to Comcast's CISO after doing a security risk exposure disclosure. Before talking to her, there were mentions of bug bounties, etc (neat). After talking to her, though, she said in a hand-wavy way that: 1. The exposure wasn't a "bug", so it's not worth a bug bounty. 2. The amount of effort it would take to start a bug bounty program would be far too cost prohibitive. In other words, "Everything's broken. We know it. If we start paying people to find what's broken, we'd go bankrupt." Heh. So yeah. Don't be surprised.
- jakelarkin 10y agoI suspect for large companies most bug bounty programs are net economic positives, especially weighed against cost of probable breaches or the comparable spend required on in-house engineering to find all the bugs otherwise cheaply and quickly identified by the bounty. The problem is social/political for senior executives to accept that discussion of flaws in the open is a good thing.
- abalone 10y agoThat is Comcast's reasoning, not Apple's. As the article notes, it's the opposite problem: Apple's internal team is running out of vulns to find.
- mahyarm 10y agoWell this guy has a bunch of ideas on how they can improve ;) https://twitter.com/i0n1c https://twitter.com/i0n1c
- bpchaps 10y agoProblem is - that's such an easy thing to say, whether it's true or false. For a device that's owned by millions, it's pretty grandiose of them to think that their internal team is all it takes. There's so much an internal team can do, so having an outside "team" is significantly better - even if it's just for a different view from a different vantage point. So, good on apple for doing this, but I'm questioning their past decisions. In particular their poor use of "they ran out of things to find" is worth discussing. The way this article is worded, their stance sounds incredibly naive, where a, "We don't have the same breadth as the infosec research community, and we would like to work with them." response might have been more appropriate. That's just my personal impression, though. edit: autocorrect fix
- abalone 10y agoI think it's more like Apple is patient and waits to get things right. Bug bounty programs are relatively new (past few years). The article notes that Apple faced a more complicated landscape than your typical company, one where state actors are bidders. So they needed to craft a more targeted program.
- hyperpape 10y agoThis seems like a pretty generic reason that doesn't explain that much. Are state actors not bidders on gmail, android, facebook, firefox, chrome?
- abalone 10y agoWhat's the going rate for an Android vuln? The FBI paid ~$1M for an iOS one. Android has a lot more malware, unpatched old installs, etc., and there are myriad ways to attack email and web accounts, so my guess is the marketplace for iOS is on a whole different level.
- mhurron 10y agoThe popularity of bug bounty programs is pretty new. Apple is often behind on things that seem to be obvious to everyone else.
- MBCook 10y agoApple has slowly been opening up, they used to be such an incredibly secretive company under Jobs there's no way this would've ever happened. Whoops. I just said "Steve Jobs never would've let this happen" line. Oh well. They're letting in third-party keyboards another extensions, small additions to Siri, releasing actual software on android, it's not too surprising that they might be willing to do this now. Been very open on swift.
- jmspring 10y agoThere was a time if you had issues with hardware, and email to Steve Jobs actually resulted in a customer escalation. I had one of the 15" MBPs that had the Nvidia chip issue, but never experienced that. But had 3 other problems -- all handled (first time for me with Mac hardware). A polite email on a friday night after I did hit my 4th hardware issue, next trip to the apple store was for a "in kind" based on purchase price replacement. Apple Software has been suffering for awhile. And where software was involved, he certainly did call teams out for failures, but we also ended up with the path iTunes is on under his watch. That said, I don't know now, but at a time, an email to Jobs did make things happen.
- deleted 10y ago[deleted]
- 0xmohit 10y agoJust trying to understand: do people begin off by writing to Tim Cook or do they use the usual channels and then end up writing to Tim?
- deleted 10y ago[deleted]
- ksec 10y agoThey still do. I email Tim Cook on issues and got a few replies. Sometimes I dont get a reply but a solution made to the problem months down the road. I believe Apple has already been listening, not as bone head as many imagine. Its just they prioritize what is important and needs fixing first.
- jtl999 10y agoAs mentioned the program is currently invite only currently (ie, https://twitter.com/i0n1c/status/761349794510036992 https://twitter.com/i0n1c/status/761349794510036992)
- Jerry2 10y agoFrom the article: >However, Apple won’t turn away new researchers if they provide useful disclosures, and plans to slowly expand the program. I'm reading this as: if you find a serious bug and report it, you'll get the money.
- bjterry 10y agoI read that as: if you find a bug and report it, you may get invited into the formal bug bounty program (but may not get a payout on the first one). No idea if that's right though.
- IBM 10y agoThe Reuters report has some details about why they limited it: >Apple said it decided to limit the scope of the program at the advice of other companies that have previously launched bounty programs. Those companies said that if they were to do it again, they would start by inviting a small list of researchers to join, then gradually open it up over time, according to Apple. Security analyst Rich Mogull said that limiting participation would save Apple from dealing with a deluge of "low-value" bug reports. "Fully open programs can definitely take a lot of resources to manage," he said. http://www.reuters.com/article/us-cyber-blackhat-apple-idUSKCN10F2TX http://www.reuters.com/article/us-cyber-blackhat-apple-idUSK...
- amenghra 10y agoTrue, but it's not like Apple doesn't have the resources to manage an open submission program.
- 10y ago
- hoodoof 10y agoI wish Apple would just fix the myriad ordinary bugs, let alone focus on security.
- mikejmoffitt 10y agoApple's finally invented the bug bounty!
- matmann2001 10y agoApple has bugs?
- xufi 10y agobugs bugs everywhere
- nxzero 10y agoWonder if they'll include their servers too; appears they're only doing the most recently released OS and hardware.
- et-al 10y agoTowards the bottom of the article they note this: The program launches in September with five categories of risk and reward: Vulnerabilities in secure boot firmware components: Up to $200,000 Vulnerabilities that allow extraction of confidential material from Secure Enclave: Up to $100,000 Executions of arbitrary or malicious code with kernel privileges: Up to $50,000 Access to iCloud account data on Apple servers: Up to $50,000 Access from a sandboxed process to user data outside the sandbox: Up to $20,000
- skizm 10y agoThe question is will they pay $1,000,000 for an exploit that unlocks an iphone? http://www.reuters.com/article/us-apple-encryption-idUSKCN0XQ032 http://www.reuters.com/article/us-apple-encryption-idUSKCN0X...
- nxzero 10y ago$200k appears to be the maximum payout.
- biot 10y agoThe article already addresses this: While $200,000 is certainly a sizable reward — one of the highest offered in corporate bug bounty programs — it won’t beat the payouts researchers can earn from law enforcement or the black market. The FBI reportedly paid nearly $1 million for the exploit it used to break into an iPhone used by Syed Farook, one of the individuals involved in the San Bernardino shooting last December. Interestingly, for altruistic / independently wealthy researchers there's an incentive to report to Apple: In an unusual twist, Apple plans to encourage researchers to donate their earnings to charity. If Apple approves of a researcher’s selected institution, it will match their donation — so a $200,000 reward could turn into a $400,000 donation.
- et-al 10y agoSmart move. That's not too shabby of a tax deduction.
- sjtgraham 10y agoI'm not familiar with the market but these seem low when you consider: - The effort required to find them - The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales, e.g. The SEP implications for ApplePay - The damage that can be inflicted on users and 3rd parties, e.g. imagine the amount of cash banks would be on the hook for if someone managed to say write a worm that used iMessage/SMS to propagate without user knowledge (e.g. with the recent TIFF vulnerability), and transfer funds from the user's bank account? Or made calls to the baseband to dial shady $10/minute premium rate numbers in some banana republic at 3AM every night? - The amount of money TLAs and black market actors allegedly pay per the TC article. - How much money Apple actually has, especially all the offshore cash that can't be repatriated to the US without incurring exorbitant capital gains. These bug bounties could be be remitted from any Apple subsidiary. - Large bug bounties would de facto end jailbreaking - Knowing Apple there would be endless NDAs and restrictive covenants before any payout is made. IMO with all this considered the max payouts seem irrationally paltry.
- dharmon 10y agoNo doubt there's going to be some low-hanging fruit (speaking relative to the experience of the participants) that is going to get scooped up quickly, so why would they open the program at something higher? Just high enough to entice the experts to pick off the "easy" ones seems the intelligent thing to do. When they go a year or two with no bugs found maybe you'll see them start upping the bid.
- frugalmail 10y ago>- The damage that can be inflicted on Apple in terms of brand goodwill and the subsequent loss of sales There is quite a bit of history where Apple has ignored security researchers who have identified vulnerabilities for quite some time before they were resolved.
- eridius 10y agoAs tptacek loves to point out, the point of bug bounty programs is not to compete on price with the black market. And in fact, according to the article, the $200k Apple is offering is one of the highest for corporate bug bounty programs already.
- jrcii 10y agoFinally, I'm going to be rich!
- zeusk 10y agoCan't wait for "We pioneered InfoSec by our first-of-kind innovative bug bounty program" @ next WWDC.
- LeoPanthera 10y agoGetting sick of the Apple-bashing. Sad to see it has reached HN, I thought it was bad enough on Reddit.
- MBCook 10y agoPretty sure it's been here the entire three years I have.
- Alex3917 10y agoIt's not just Reddit. Look at MacRumors, they are absolutely furious with Apple right now: http://www.macrumors.com/2016/08/01/apple-new-ipad-pro-computer-replacement-ad/ http://www.macrumors.com/2016/08/01/apple-new-ipad-pro-compu...
- curiousgal 10y agoWell in fairness that is a pretty stupid marketing plan. Seems like they are trying too hard to come up with pseudo-deep punchlines.
- coldtea 10y agoYou know that's not Apple but some advertising company, right?
- michaelt 10y agoAd agencies usually present their plans to the client for approval before filming, and present the film to the client for approval before broadcasting. It's not like this got broadcast without Apple's marketing team's sign off.
- 0xmohit 10y agoCharlie Miller must be happy. https://twitter.com/0xcharlie https://twitter.com/0xcharlie
- honkhonkpants 10y agoI wonder if they are backfilling rewards to any of the external researchers who have been doing all of Apple's security research for the last decade. Just as an example, a single researcher from Google is credited with 11 separate vulnerabilities that would qualify for the $50k reward, in a single patchlevel of OS X (and the same person had five such credits in the patchlevel prior to that!). That's almost a million bucks worth of rewards in only half a year of disclosures.
- eriknstr 10y agoI don't think it would make economical sense for Apple to pay for something that they already got for free.
- honkhonkpants 10y agoSure, but it would be a gesture of goodwill and a way of making amends for years of freeloading.
- nathanvanfleet 10y agoThat guy did 10 more after the first freebie. Could it be that something else was motivating him?
- Godel_unicode 10y agoI believe the researcher in question works for project 0.
- tptacek 10y agoAmong the many reasons this is very unlikely to happen, the bounty values we see now account for the increased difficulty of finding these kinds of vulnerabilities in iOS since its earliest releases. This is an OS that was designed as a platform for secure applications --- that's part of the premise of apps on the Apple phone --- and it's gotten much harder to find and exploit vulnerabilities on the platform since that release.
- godzillabrennus 10y agoNext they need to offer a bounty program for usability issues. iOS needs a lot of love since Forstall got squeezed out.
- nikofeyn 10y agoiOS? what about mac os x? it's completely stagnated if not gotten worse from a usability standpoint.
- jordache 10y agohow about you fix bugs that are already well known, like how the sd reader dies after a while in el cap?
- amenghra 10y agoThat has nothing to do with security.
- joebergeron 10y agoThis is definitely a step in the right direction. They say they're worried that their bounties won't be enough to dissuade anyone only interested in money from disclosing vulnerabilities to malicious sources. Honestly I think that a lot of people who discover these vulnerabilities would rather be paid slightly less money by disclosing to Apple and have the rep/CV fodder of "I broke Apple" that comes with a responsible public disclosure, than going through secret channels to make slightly more money at the risk of potential legal trouble. And anyways, 200 grand is an astoundingly high ceiling for bug bounties; highest I've ever seen paid out was a "meager" 20k by Uber, and I thought that was a lot of money for a bug program at the time.
- pepijndevos 10y agoAm I reading it correctly that this is only iOS, and not other Apple software?
- alfanick 10y agoI've once found security bug on OS X/Mac (low chance of occuring, however gives complete access), reported complete steps to reproduce and solutions - received moreless copy-pasted response - two years, two OS X versions later - the bug is still there, even though it looks like 5 minutes fix...